Cloudflare said on Monday it has applied for inclusion in the Chrome, Apple, Microsoft and Mozilla root programs as it seeks to become a public certificate authority (CA).
The company said it has also signed a definitive agreement to acquire an established, broadly trusted root from GlobalSign so it can offer certificates with the widest possible device reach from the day it begins issuing.
Cloudflare said it is not issuing certificates yet and that it will be some time before it does. It said it plans to be one of the first CAs to serve post-quantum certificates, targeting Chrome’s recently announced Quantum-resistant Root Program.
For more than a decade, Cloudflare has been one of the largest consumers of publicly trusted certificates on the Internet without issuing any itself, the company said. It said it sits in front of more than 20% of global Internet request traffic and terminates TLS for millions of domains, relying on millions of certificates per year provisioned through multiple CAs.
The company said a newly created root takes years to become widely useful because it must propagate into operating systems, browsers and devices, and never reaches devices that no longer receive updates. The GlobalSign root it is acquiring has been trusted across browsers, operating systems and devices since 2012, while the new root it will submit to root programs is built for newer policies, including programs that cap how old a trusted root may be.
Cloudflare said the free, automated certificate model now carries most of the encrypted web, much of it through Let’s Encrypt, which issues on the order of 10 million certificates a day, serves more than 500 million sites and passed four billion active certificates in 2025. Cloudflare said this concentration carries systemic risk, because much of the web would have no comparable free, automated alternative if the dominant free CA suffered an outage.
The company said its CA will be Automated Certificate Management Environment (ACME)-first, allowing anyone already using an existing free CA to switch by changing a directory URL. It said it will issue only to clients that support ACME Renewal Information, standardized in RFC 9773, making renewal automation a condition of issuance so certificates can be replaced quickly when they must be retired.
Cloudflare said it will publish reproducible builds of the software that signs certificates, attest the hardware security modules holding its keys, and run a public dashboard for issuance health and incidents. “We want root programs, researchers, and ordinary site owners to watch how a modern CA actually operates between audits,” the company said.
The company said it plans to be one of the first CAs to issue production Merkle Tree Certificates, a more compact certificate format designed for a post-quantum world, with the first certificates issued in the first quarter of 2027. It launched Universal SSL twelve years ago, during Birthday Week 2014, which it said nearly doubled the number of encrypted sites on the web overnight by providing free TLS to every site behind Cloudflare.

